Telephony LIVE

THE 2008 TELECOM SUMMIT

Introducing Telephony Live: The 2008 Telecom Summit -- the second annual, two-day conference from the editors of Telephony magazine.

Learn more

         Subscribe in NewsGator Online   Subscribe in Bloglines

Zombies threaten ISPs

more on the topic

More Related Articles

Zombie computers are the single biggest threat to ISPs, according to an annual security survey conducted by Arbor Networks, as compromised PCs are being used to spew out spam, launch distributed denial-of-service (D-DOS) attacks and perpetrate identify theft and phishing schemes.

About 60% of the ISPs surveyed identified zombies as either their primary or secondary threat, said Mike Hollyman, manager of consulting engineering, for Arbor Networks. Zombies--or “botnet” computers, as they are also known--are PCs linked to the Internet that have been taken over, without their owners’ knowledge, and can be used to send email, store information or run programs. While there is nothing new about botnets, Hollyman said, they are being used more extensively and in different ways.

“They are definitely doing more things – like launching D-DOS attacks, sending spams, serving as open proxies, and being drop sites for storing ID information, and for phishing sites,” he said. By using a widely distributed set of PCs, criminals can use one set of zombies to send out spam with a phishing message and, when an unsuspecting customer provides log-in and identity information, store that on a different zombie computer which can be anywhere in the world, Hollyman said. The traffic flows are more widely distributed and not as easy to detect.

“That makes it harder for law enforcement to track down,” he said. “The way they are created these days, it is easy to select individual hosts they want to use in nefarious ways. They may pick a botnet for a phishing attack that is in a site where there is no legal enforcement or the resources are limited.”

According to survey respondents, networks of zombies have become smaller and more adaptive, with “more firepower and more effective attack vectors,” Arbor reports, as well as better organized command and control servers that use peer-to-peer communications.

D-DOS attacks are the most common use of botnets and can take down Web sites and e-commerce operations, Hollyman said. Survey respondents say these attacks are getting more professional and therefore more disruptive.

“The largest attack has gone up to 24 Gb/s, which is 2.5 times the average link speeds,” he said. “One of those attacks could cause severe collateral damage, and we have seen that in last 12 months. As service providers start to monitor deeper into their networks, they are seeing these attacks might be impacting their infrastructure.”

That means an attack against a specific customer site – and most attacks are that specific – has collateral impact on other customers served by the same network aggregation device.

Service providers are acquiring in-house expertise to address security issues as concerns have grown, Hollyman said, but they could use more help from law enforcement.

“They are proving they have the in-house skills, and they are no longer just packet pushers, they are in the position to gather information from security that will lead to global changes to attack vectors,” he said. “What they need now is better law enforcement options. Today, the response is fragmented. Many attacks involve multiple providers and multiple law enforcement entities and that can be difficult to manage.”

Get Updates Via Email

related resources

Want to use this article? Click here for options!
© 2008 Penton Media Inc.

Webcasts

WEBCAST

Telephony’s Inside Telecom Live: Building an efficient IPTV content supply chain

Find out! Watch Telephony's LIVE Webcast July 23, 2PM ET/11AM PT. Telephony will delve into what is required to create an efficient IPTV content supply chain. LEARN MORE or REGISTER NOW.

White Papers

WHITE PAPER

Intelligent Optical Control Plane Architectures

This paper explores the benefits of optical control plane functionality for service providers. DOWNLOAD NOW

Podcasts

PODCAST

Telephony Podcast: Ifbyphone CEO Irv Shapiro

Telephone application platform startup ifbyphone has built a building block platform for assembling web and telephony integrated applications. LISTEN

Blogs

BLOG

Belt-tightening and broadband

AT&T’s earnings report today was not as bad as some had feared. But one particularly gloomy aspect was the slow growth in broadband.READ

E-Books

E-BOOK

READ E-BOOK: MANAGING THE CUSTOMER EXPERIENCE

This e-book explains how to keep your customers happy, reduce churn and strengthen profits. Sponsored by CA’s Wily Technology Division. READ NOW!

TV

TV

Interview with Jim Hansen of Embarq at NXTcomm08

Tune in to Telephony TV to watch an interview with Embarq's Jim Hansen at NXTcomm08. WATCH IT NOW.

  • Telephony Content
  • Telephony Content

current issue

Current Issue

July 14, 2008

The chip-making giant is again driving into the wireless processor pool, expecting to make a bigger splash as computing gains prominence in mobile devices. Read Now

NXTcomm08 Show Daily News

Get up-to-the-minute news from NXTcomm08 -- before, during and after the show! Hear interview podcasts, announcements, commentary and more. Visit www.nxtcommnews.com!

more news

Global >>

MORE

Ethernet >>

MORE

Independent >>

MORE

IPTV >>

MORE

IMS >>

MORE

WiMax >>

MORE

VOIP >>

MORE

FTTX >>

MORE

Access >>

MORE

Broadband >>

MORE

Wireless >>

MORE

Software >>

MORE

Podcasts >>

MORE

Get Updates Via Email

Browse Issues

  • July 14, 2008
  • June 30, 2008
  • Jun 16, 2008
  • May 19, 2008
  • May 5, 2008
  • Apr 28, 2008
  • Apr 14, 2008